Vulnerabilities (CVE)

Filtered by CWE-89
Total 20788 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-35750 1 Wpdevart 1 Gallery 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevart Responsive Image Gallery, Gallery Album.This issue affects Responsive Image Gallery, Gallery Album: from n/a through 2.0.3.
CVE-2024-35736 1 Themeisle 1 Visualizer 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle Visualizer.This issue affects Visualizer: from n/a through 3.11.1.
CVE-2024-35678 1 Bestwebsoft 1 Contact Form To Db 2026-06-17 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BestWebSoft Contact Form to DB by BestWebSoft.This issue affects Contact Form to DB by BestWebSoft: from n/a through 1.7.2.
CVE-2024-35630 2026-06-17 N/A 7.6 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue affects WP TripAdvisor Review Slider: from n/a through 12.6.
CVE-2024-35548 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.
CVE-2024-35511 1 Phpgurukul 1 Men Salon Management System 2026-06-17 N/A 4.7 MEDIUM
phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/index.php.
CVE-2024-35469 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 9.8 CRITICAL
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVE-2024-35468 1 Oretnom23 1 Human Resource Management System 2026-06-17 N/A 5.4 MEDIUM
A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
CVE-2024-35409 1 Webidsupport 1 Webid 2026-06-17 N/A 9.8 CRITICAL
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
CVE-2024-35361 2026-06-17 N/A 9.8 CRITICAL
MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.
CVE-2024-35359 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection.
CVE-2024-35358 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 6.5 MEDIUM
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_category. Manipulating the argument id can result in SQL injection.
CVE-2024-35357 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 5.3 MEDIUM
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection.
CVE-2024-35356 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 6.3 MEDIUM
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_item. Manipulating the argument id can result in SQL injection.
CVE-2024-35355 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection.
CVE-2024-35354 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_category. Manipulating the argument id can result in SQL injection.
CVE-2024-35350 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument id can result in SQL injection.
CVE-2024-35349 1 Dino Physics School Assistant Project 1 Dino Physics School Assistant 2026-06-17 N/A 9.8 CRITICAL
A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection.
CVE-2024-35305 1 Artica 1 Pandora Fms 2026-06-17 N/A 9.8 CRITICAL
Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.
CVE-2024-35286 1 Mitel 1 Micollab 2026-06-17 N/A 9.8 CRITICAL
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management operations.